Darren Anstee, CTO for Security at NETSCOUT, discusses the cyber risks around major sporting events. 

Cybercriminals used to cause disruption by focusing on stadium systems and broadcast feeds during major sporting events, but they appear to be broadening their scope.

According to new research from NETSCOUT, distributed denial-of-service (DDoS) attacks across Italian infrastructure jumped by 181% during the Milano Cortina 2026 Winter Olympics. Hackers still targeted venues, but also went after local transport networks, hotels and tourism services.

With modern events relying on digital tech, a crash on a ticketing platform, payment system, or transit network can ruin a fan’s experience just as easily as a blackout inside the stadium.

Insider Sport sat down with Darren Anstee, CTO for Security at NETSCOUT, about how threats are changing, why hacktivists are looking past the venue and what organisers must do to protect their operations.

Read the full interview below.


Attacks around Milano Cortina 2026 spanned before, during and after the Games. Where do you now see the most vulnerable window and has that changed compared to previous events?

Darren Anstee, CTO for Security at NETSCOUT
Darren Anstee, CTO for Security at NETSCOUT

Attack activity is commonplace throughout the duration of a major international event, but what has changed is the way in which individual events can spur spikes in activity due to geopolitics. What has also evolved is the breadth of the threat surface that must be defended, with attackers no longer only focused on targeting video streaming and other high-profile targets, but also on hitting transport, hotels and other secondary targets within the digital supply chain. 

During the 2026 FIFA World Cup, intelligence showed that hacktivists were active in the weeks before the opening match. This pre-event window gives attackers an opportunity to scope the defensive capabilities arrayed against them. For organisers and sponsors, securing this preparatory phase is essential. If digital services are disrupted before the opening whistle, the financial and reputational damage may already be done, regardless of how well the event itself is protected.

A lot of the targeting appears to have focused on hotels, transport and tourism systems. Is this the default entry point for attackers and are organisers still too focused on protecting broadcast and competition systems? 

Historically, a lot of emphasis was placed on shielding core stadium infrastructure, internet service provider (ISP) infrastructure, content distribution platforms and primary sponsors. However, when assessing recent tournaments, we have seen threat actors increasingly looking at the wider event ecosystem.

Hotels, transit networks, ticketing platforms, payment and tourism services are attractive targets because they often rely on sprawling, interconnected digital supply chains. These secondary targets are just as important to the overall event experience. By targeting these services with DDoS attacks, hacktivists can more easily create operational disruption and raise their profile.

The threat surface for global events extends far beyond the venue turnstiles. If a fan cannot board a train, access a ticketing portal, download a promotion from a sponsor or check into their hotel, the event’s reputation takes a hit.

Groups like NoName057(16) claimed responsibility for attacks during the Games. How blurred is the line between independent hacktivism and state-aligned operations when it comes to major sporting events? 

Historically, hacktivists often operated as loose, independent collectives driven by localised social or political causes. Today, groups like NoName057(16) may remain fully independent, but their targeting often follows wider geopolitical conflicts. And, in fact, we have recently seen hacktivist groups collaborating in attack campaigns, where there is very close alignment in targeting.

The unfortunate truth is that almost any organisation can be targeted, even if they are not political or politically aligned. Attackers often select targets because of their vertical, geography or association with a culture – and in some cases, where automated targeting is used, even the name can be enough.

Attribution remains complex. The more practical point for organisers is that they cannot rely on assumptions about motive. Whether an attack is independent, ideologically aligned or state-adjacent, the operational impact can be the same.

Milano Cortina 2026 Olympic crowd at barriers with flags and snowy mountains during winter games in Livigno, Italy.
Editorial credit: Andrei Antipov / Shutterstock.com

To what extent are these DDoS attacks designed to cause operational damage versus making a political statement at moments of peak global attention? 

This is very variable, I’m afraid. Some actors are very much about making noise, while others are focused on actual impact. This isn’t specific to sporting events – rather, this is a split in behaviour we see across hacktivist groups more generally. 

What’s key with major sporting events is that they are globally visible and symbolic targets. Given the intensity with which pro-Russian hacktivist groups have targeted Western and NATO-aligned nations and organisations since the Russia-Ukraine conflict began, sporting events act as a focal point to make a political statement.

For organisers, the priority is having the threat intelligence and real-time visibility needed to understand attack behaviour quickly, adapt mitigation and preserve service performance and availability.

Looking at the 2026 FIFA World Cup, how does the multi-country format change the attack surface? Does fragmentation across jurisdictions make defence harder? 

The multi-country format of this World Cup expands the digital attack surface significantly, requiring a lot more coordination across many more organisations. There are different operational models, languages and governments in play, all looking to defend a vast array of targets.

The US, Canada and Mexico each have distinct cybersecurity regulations, governing bodies and operational processes. When a sophisticated, multi-vector DDoS attack strikes, these cross-border differences must not slow down incident response, so a lot of planning and coordination has been done in advance.

We’re seeing more use of automation and AI in fraud and cybercrime. Are DDoS campaigns around major events becoming more adaptive or targeted as a result, or is volume still the strategy? 

When it comes to DDoS, AI is being used as an automation and orchestration engine. The DDoS tools and services out there have been able to combine high volume and sophistication for a while in the attacks they generate, but at the direction of the user. Now, AI tools can do that on their behalf, making it much easier to launch recon-driven, sophisticated attack campaigns.

For major sporting events, organisers and stakeholders must be aware that volume and adaptability are no longer mutually exclusive qualities. They need actionable threat intelligence and adaptive DDoS defences that can keep critical services available.

There’s a sense that every major event is ‘better prepared’ than the last. What has improved in how organisers defend against these attacks, and where are we still seeing the same mistakes repeated?

Ahead of major sporting events, organisers, sponsors and everyone related to supporter experience, from content distributors to transport providers, are generally well prepared.  

Protection against attacks must be layered, combining on-premise capabilities for key infrastructure, such as firewalls, load-balancers and application servers, with cloud- or ISP-based defences to handle larger-scale traffic floods. Organisers have realised that the key to successful defence isn’t just technology – it’s cooperation between all of the organisations involved. The level of planning around this, threat awareness and investment in resilience have all genuinely improved.

Previous articleLIV Golf agrees lead investor deal after PIF funding exit
Next articleSideline Moves: MLS names Berg to succeed Garber as boardrooms reshuffle